PT-2024-3564 · Microsoft · Edge

Sazzad Mahmud Tomal

·

Published

2024-05-10

·

Updated

2025-01-17

·

CVE-2024-30055

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Edge (Chromium-based) versions prior to 124.0.2478.97
Description The issue is related to errors in the representation of information by the user interface, which can be exploited by a remote attacker to conduct spoofing attacks. There are no known exploits yet, but it is recommended to patch as soon as possible for defense-in-depth.
Recommendations For versions prior to 124.0.2478.97, upgrade to version 124.0.2478.97 or later to mitigate the risk of remote exploitation. As a temporary workaround, consider restricting access to sensitive information until the issue is resolved.

Fix

UI Misrepresentation of Critical Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03869
CVE-2024-30055

Affected Products

Edge